CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack
In Flowmon versions prior to 12.5.5, a vulnerability has been identified that allows a user with administrator privilege
Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78]
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote a
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote a
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote a
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Inf
A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, US
Diagnostics command injection vulnerability
Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('
Nagios XI versions prior to 2024R1.3.2 contain a remote command execution vulnerability in the WinRM Configuration Wizar
Nagios XI versions prior to 2024R1.4.2 contain a remote code execution vulnerability in the Business Process Intelligenc
Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management function
Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run C
FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user
Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppManagementController.app
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and abov
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in NCP-HG100 1.4
Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the experimen
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul
A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave
Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vul
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7
WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Ser
RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_specia
RG - AP180, Indoor Wall Plate Wireless AP AP180 series provided by Ruijie Networks Co., Ltd. contain an OS command injec
PhotoShow 3.0 contains a remote code execution vulnerability that allows authenticated administrators to inject maliciou
DreamFactory saveZipFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attacke
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in
MaxKB, which stands for Max Knowledge Base, is an open source knowledge base question-answering system based on a large
A malicious or compromised MacPorts mirror can execute arbitrary commands as root on the machine of a client running por
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" p
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eMinute
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" p
The ns_backup extension through 13.0.0 for TYPO3 allows command injection.
A physical attacker with no privileges can gain full control of the affected device due to improper neutralization of sp
In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a user who holds a role that contains the high-priv
A potential command injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started